# Harmonising Security and Compliance in Digital Asset Infrastructure - Pavle Krivokuca | Fireblocks

- Channel: [ETH Belgrade Community](https://streameth.org/eth-belgrade-community)
- Date: 2024-10-07
- Duration: 30:19
- Topics: People & Blogs
- Watch: https://streameth.org/watch/yt-JHfLYV6q1X8
- YouTube: https://www.youtube.com/watch?v=JHfLYV6q1X8

## Transcript

thank you thank you uh quick question who's passionate here about compliance okay that's that's far more than I expected when I when I started working in the area and I was like okay I'm going to be working on compliance products like okay how how how Dynamic and interesting can be and it's it was a revelation for me basically uh what I'm what I'm going to be sharing as part of this presentation are a couple of pointers uh besides the intro itself um I'll be just running through some regulations I I know this track will be hearing a lot about regulations regulatory Frameworks whatnot um during the day but I'll be mostly focusing on the the last three points basically going a bit more in depth around kyt travel rule uh what does it mean in practice uh very briefly on some of our products we are basically developing and and working on and mostly about some insight we found with working over with 200 customers in Solutions when they have ual compliance need and what does it actually mean in practice uh just as a short uh context and introduction I'm I'm my background is in Business Development I've been working with big um crypto blockchain uh companies for past three years and um generally I before that I was working with a bunch of startups helping them get their ideas to Market and find an investment so I'll be speaking also a bit maybe from a you know that perspective of you know building something end to end and making making sure that you know it's being used and it's being uh leveraged in a proper way and in free time I'm I'm wor working so if anybody's passionate about that you can also approach me in the break um about fire blocks uh I I I guess a good percent of people know uh what fire blocks is just to kind of pin you a picture and give you a context we basically at this stage close to an ecosystem we offer a a big variety of different uh Solutions and tools roughly speaking around uh 20 20 5% it varies obviously of all blockchain transactions are happening around infrastructure so I would say we have a fairly big uh you know overview of customers and the actual use cases that are that are happening uh the the products itself vary from everything you know secure custody interacting with 60 plus blockchains uh you know operation uh operationalizing the governments using different Dynamic policy sets and configurations you can basically control and automate a bunch of things uh we have a huge uh fireblocks network of counterparties of over thousand uh different counterparties who are using uh different ways to interact directly with each other uh with te and last but not least on the D5 and web3 exercise we offer a wide spectrum of different different connectivity uh just to kind of give you uh you know a size context we have roughly around 1,800 customers uh and a bunch of wallets uh and transaction that are happening on a monthly uh monthly basis these are some uh just of the uh clients who are using basically our infrastructure for um for their work uh also uh one last last point on the fireblock side I'm very happy to say that for year and a half now we have a Belgrade office uh and actually compliance and security team working on this solution is basically sitting here and developing this so we're very proud of that and uh we we actually have a couple of openings now so do check out our page I think we have four or five different openings um on for the Belgrade office uh that being said uh let's let's jump into the to the actual content of the of the talk um as I said not going to go deep diving into regulations uh too much just kind of giving you a very quick overview uh we can you know uh and I'm not kind of going in the perspective kind of let's say political or conceptual philosophical conversation is this good is this bad it's here like some might some might argue that you know it's against blockchain values that it's regulated that anonymity is very threatened like is this good how are we treating that not going into that like the regulator Regulators are here regulations are becoming more and more specific with each month and the ask that are required from everybody who is interacting with digital assets are bigger and bigger than ever before and what we're seeing as a as a kind of trend uh from from the ground is that even the regulations that were very kind of open-ended for interpretation are becoming much more specific and much more concrete and Regulators are actually asking uh you know virtual asset service providers anybody who's kind of interacting with digital asset in a certain way to actually go in depth and understand okay are you doing the proper thing we heard a couple of examples of the previous talk on you know what can happen and how can you know courts and let's say officials look at different things that are we are working in the in the whole Space um to give you a flavor uh like different regulations across the world are coming uh you heard about Micah probably and then across the world we're seeing a bunch of different specific and blockchain specific digital asset specific regulations coming in so it's definitely there it's not going to go the only question is how it's going to shape up and B what are we going to do as you know Builders infrastructure providers uh to basically you know uh make sure we're we're doing a proper thing and it's at the end of the day legal and compliant nobody wants to end up in jail uh at the end of the day uh you can also see here the overview of you know regions and what's kind of popping up and what are the specific asks that are coming from different you know uh Regulators perspective when you're interacting with digital asset again not going into specific but as you can see big players worldwide are getting more regulated and we need to make sure that you know on one side we follow those regulation and on the other side we actually can do whatever our business model is is it an OC desk is it a you know a centralized exchange is it whatever we're trying to make and do that it's you know still you know technology that we actually want to want to push for um what I'm going to be focusing on are basically kyt a and AML and travel rule landscape those are some of the things we have been focusing on in the past past period so basically just as a quick crash course and I know most of you know this but uh for those of you who don't when we speaking about the kyt knowing your transaction context um the the general push from Regulators is making sure we have a right enough context when we are interacting with a specific transaction and we actually know what's happening there like obviously a bunch of that is publicly accessible you know if you go to any node and you can actually check out what's who's doing what but you see a bunch of numbers you see a you know bunch of data being pulled out there but do you know who it is do you know who you're sending it to do you know have they any specific ties or limitations and obviously you know the worst thing you can Pro probably do is you know doing annoyingly something that can be deemed illegal or or not good U more specifically if we're speaking about the AML side of things any money laundering you know the way I explain it to myself you know it's making sure not sending the terrorist the money so whoever is deemed as terrorist again a completely different in the political conversation but here looking at the on the definitions we don't want to be sending money to the bad guys and we need to prove uh to local authorities if us that we have policies systems in place so we don't do that and we have redundancies and back options that we don't actually doing knowingly or or unknowingly and you can actually see it we we we had conversation with some of the uh houses that are doing you know reviews of these policies that you know it's not even enough that you have one thing in place uh on on previous talk somebody like said like there was like a example of oh we have ch analysis now we're seeing Regulators coming in and you know asking about do you have a double tax stack do you have a backup what if CH analysis doesn't work do you have policies configured in a way that is sync with your local laws and local requirements so it's becoming more and more complex and you still you know you're doing your regular operations like I I when especially when we were you know I was entering the field there was a kind of VI of oh it's a thing we need to do for regul s kind of you know a check of the box I do it on the side and you know I'm good now we're seeing customers coming back and Diving much much more in depth and actually making sure that they don't do anything that might be being potentially susp suspicious or has a high high risk rate on the other side um we have a you know new reg new in in the regulatory context new kind of thing which is travel rule I'll be speaking more about it later but basically if you imagine it is something most close to Swift which we have in traditional finances so basically what happen is that to be travel rule compliant alongside with your regular transaction information which is your your originator address sender address amount asset you know the usual ones you can find you actually need to accompany a bunch of let's say U metadata in a way alongside with that transaction so you are travel rule compliant that data is super touchy because all of it is deemed pii information so person person n information you can ask for everything geographical address name and surname social security number a bunch of kind of different data points there that different jurisdiction might deem necessary because they're trying to contextualize and say if you know who are you're sending through and where it's coming from the chance of it you know being an illegal action or that you can defend yourself in code oh we didn't know what we were doing becomes much much much uh less what we have as a as an issue and I'll be discussing that in the last part of of the talk is the whole uh Sunrise issue the travel rule has today because it's a new thing nobody's actually really sure how to do it fully you have different interpretations and you know you have uh just now bigger players uh getting on boarded to it so you want to make sure that you're building a relevant products and you're doing you know uh concrete things there uh and yeah as you can see uh Trend one as I mentioned AML this is the the cfts and General requirements from wasp are becoming pretty much your vanilla flavor of regulations it's not like do you need it it's just how much you need it and how are you going to make sure that you actually you know AML compliant at the end of the day whichever provider solution inhouse or third party you're using at the end of the day on the other side is the travel rule um and you you know we can call it harmonization we can call it you know um how are we getting onboarded collectively on a global and individual Regional levels with the whole context and problematics bottom line is it's here it's going to be much more specific than it is now and the regulations are going to be much much more let's say Hardline than they were before which were kind of you know we were in a area of oh kind of I'm doing my best you know oh I have some integration are all the transactions going through that integration are all them being checked Ah that's a story for another day the another day is here you need you need to make sure you doing doing the right things so uh I I'll be sharing also some insights we've seen from from the grounds up working with customers on these Solutions just to give you context what what are we basically offering and doing we we're providing in Integrations with two on two two front so both kyl and travel rule um the access is both through our API and console and the the general idea behind that is on top of the Integrations we have with different providers we are offering up policy layer of customization when where customers can actually set a bunch of different rules and you know configs so they have automatic checks and making sure we don't send something you know to the bad guys at the end of the day um today what we have are direct Integrations with chainalysis both V1 V2 elliptic and elliptic holistic which is their V2 and on the Travel rule side we developed a first ever on the market direct integration with notab Ben and we also provide you some basic uh trust uh travel rule protocol support um what we're basically seeing across the field is that uh customers uh there's a growing appetite from customers to have Solutions like this in place uh we're also in communication with a bunch of different other let's say smaller or mid-market players on the IML provider side and it's there it's needed and customers are using it more and more to give you context I was just looking at the last month numbers and around 18% of all fireblocks transactions we have today are screened um and it's growing and it's grow ever growing number so there something which which is picking up especially in I would say from from our angle in last year or so and we're seeing a large number of customers you know wanting solution implementing solution because again Regulators are coming they're asking very specific things and you need to make sure you know you're compliant in the end of the day U just to just to paint you a picture of what we generally do are our compliance checks are very early on in the transaction life cycle that we are supporting for our customers on the far blocks platform so what we generally do both for outgoing and incoming scenario transactions we have something called screening policy when customers Define out of all the transaction volumes what are the ones they want to screen and check against the the specific either AML check or travel rule check uh and then based on that we send it to provider provider gets us gets the response of underlying race called travel rule compliance and then based on that we make a verdict uh actually we we help customers to make a verdict through defining the post screening uh post screening policy what's kind of interesting there is that you know obviously this came from from kind of customer asks uh based on you know you might not be wanting to doing uh some checks for different types of transactions like you know you're doing internal transfers you know what's the context you know who you're sending through so you don't want to be going going through this obviously the the Delta when we're kind of communicating with the provider varies on the risk level varies on the multiple kind of factors that we're seeing across across different providers but you get the general idea you know we we don't want to be uh let's say allowing in a way our customers to send something through which is not deemed safe by the internal policy whatever their internal compliance policies may be so if you know and then it's you know kind of interesting because like you if if you look at at different customers they might be having a completely different kind of configuration some let's say if I receive a transaction that is uh connected to let's say gambling venue some uh customers might say it's a high risk for us we don't want to be touching their transaction because it's out of the bounds for us While others let's say customers who are interacting with gambling VES is completely you know fine with them but then you also want to make sure that you know that uh you know address that you're interacting you want to interact with is not on ofx sanction list it's not being deemed as a high risk from other parameters or that you know in case of the travel rule you're actually sending all the necessary information through to be travel rule compliant um let me just check we're we're good on the time um I'll I'll share four uh key insights of something that we have seen from the from the practice and also feel free uh we're going to have some some time for questions just to kind of show them show them organically um just to kind of give you a context we're roughly doing around two and a half million screenings per month uh for our customers and roughly 250 customers are using our our products uh each month um so Insight number one the uh let's say speed versus safety conversation uh depending on the customer profile we're seeing um and on the business model they have the speed might be a key parameter for them which means that they're going to have a very limited window um on which they need to realize the transaction so they're not going to be able to wait too much for the information and feedback there um usually like uh these these business models they would say oh we just want to check it out send it out and if you receive the result of the of the check fine let's apply it and act on it if we don't we're treating it as a kind of you know oh uh I did my best in the time I had I did my best and this is what we received we tried to check but you know let's let's move forward on the other side of the spectrum on the more safety side we seeing customers who are basically saying anything that is not low risk is being stopped we don't want to interact we don't want to touch that we don't want to send that transaction through we we don't care if it takes 10 minutes even or 15 minutes even to get the result we're we're we're actually you know we're going to wait until it basically hits and we receive the result from a provider and based on that act accordingly those are two extremes and then everything in between um what's good and what I can say is that we're getting less and less customers using it in a way of speed because regulation is coming and you actually need to make sure that you know you have things in place and you're doing the right thing when you're interacting with different uh you know different especially unknown address addresses or addresses you know uh that might be deemed risky you know uh directly indirectly however you kind of like like to de de me there um also what's kind of uh interesting Trend that that we're seeing from a kind of safe safety side of things is that customers are getting more and more into very specific and more complex policies um internal compliance policies that than they used to have again going to the point of they want to make sure they doing right by you know different leg rators or especially if they're doing kind of international business and they have to kind of follow different local jurisdiction and regulations that that they are second Point uh what I wanted to share and that I briefly mentioned is the whole Sunrise issue of the travel rule that we are generally seeing the the travel rule was a it was a big hype uh especially last year a new regulation coming in a new Need for that uh there there is generally still very big appetite for implementing travel rule checks the the problem that the whole industry is uh facing is that not enough counterparties are travel rule compliant meaning that you know you when you send something you know from point A to point B and point a is compliant and has the right information and you know you did everything you could on your end um you have the problem of is the party B travel rule compliant and do they have the necessary information and context so we can actually piece the puzzle out and say oh we have you know the travel rule message is complete because we know have the data end to endend and we know the context of the sender and receiver and we can you know provide a proof of that to our uh to our Regulators if they ever come asking um the the the trick there is that what what we're basically seeing is a very kind of um let's say layered approach to onboarding uh to travel rule uh meaning that you're probably going to see uh customers first doing it on themselves and they're saying we're doing our best you know we're sending the info we we we can out there and then we're hoping to get more and more counterparties involved so they're also sending their their information there and what what we've seeing also is that Regulators are fairly okay with that they're saying we understand the sunrise issue we understand it's going to take time um for it to be fully you know fully in place and then they're ready to say okay let's collectively do our best to go into that but you know not speaking about time Horizon but let's say I could imagine a scenario in let's say one two three years from now then when it's going to be a much you know more specific and not so much the best uh you know effort kind of basis um and also uh you can also see that by the reg regulations being pushed and I remember specifically for MAA I think it was pushed three or four times so far I know it was supposed to go out at one point September last year then it got pushed you know know to later end end of the year and then it you know um is coming on this year so it's also Regulators understand that uh but also do mind that what you're seeing from customer perspective especially around the let's say travel rule type of checks when they are required to get a bunch more information than they uh you know that they have it takes time to integrate like we're seeing customers taking months to integrate with these Solutions because out of the blue they need to start uh collecting a bunch of additional data H which which brings me to the to the third Point uh one of the nature of the travel rule as I mentioned is sharing a bunch of pii very sensitive data along the way uh so imagine you were let's say a bank a bank a doesn't really matter how how big you are or let's say you only focus on digital part of things you know you're very focused on digital assets you know blockchain wow everything is amazing you're specifying for that and then out of the blue there is a regulation coming in asking that you need to send uh let's say in in the name of your user a bunch of information like okay name surname email address you probably already have social security number geographical address a legal entity name a bunch of other things do you have it do you store it in your DB do you store it safely in your DB are you ready with your architecture and layers you have in place to share that pii data in encrypted way with the counterparty so the travel rule message gets you know checked so you need to start thinking uh on these things and especially like I I I would even make an argument that it's not depending how big you are like very big or very small you're going to have you know to change a few things the way you are doing so far if you didn't plan to collect that type of information store it and and and secure it at the end of the day uh so it's one of the one of the things that is very interesting because we've seen customers who do they do take time when integrating with travel rule solution but then the the biggest kind of obstacle for them is making sure they actually have a way to collect the necessary data you know and actually store it in a proper way from their users like imagine being a bank with a million users and obviously it's not even the biggest bank you have 10 plus million users easily and you need to ask them oh you know what you need to provide me these new 10 data points to be able to send the transactions through because we have a new regulations coming in so you can imagine the compliance legal marketing product however you like problem that you have across your organization that you need to kind of communicate and build a good enough solution to to actually you know make it happen at the end of the day uh and four Insight I wanted to share is you know building a scalable solution from right on and I think you know maybe this is more coming from you know product and Ary perspective uh but uh one of the let's say I would say I would say a rule of th Trend but especially when you're in development is saying yeah yeah we're going to solve that you know scalability issue once we get there we had situations when we saw customers to Xing in a matter of less than a year and using the products which is on one side amazing you know I'm saying oh the product is being used it's it's relevant it's all is good but then you need to you know check are you processing enough of transactions in a second can you support you know different needs and configurations uh did you think about how it's going to impact customers operations and you know especially if we have a collective mindset of oh I'm integrating with a risk travel rule whatever provider just to check on the box from a regulatory perspective and now you have to implement that on a bunch variety if not all of the transactions you're doing and it's impacting your transaction processing time it's impacting your you know to end time it just becomes crazy like did you think about it did you did you plan ahead did you how are you communicating that with your customers uh because you know these things do take time even know you know providers are collectively working on their improving on the speed of getting and fetching the results because there's much more data than it was before it still takes time to conduct these checks you know in some scenarios you have like oh we're going to get a result in couple of seconds in some scenarios is not getting results in 15 minutes imagine having a piss customers on customer on the other end you know yelling at you why my transaction is not going through and then to spice everything up um it's the regulation uh is coming from let's say a traditional Finance context where they didn't have a problem of you know blockchain blockchain you know confirmation uh blocks how much time different blockchains need to conduct different things and then the obvious differences with different blockchains how do you interact uh and then how do you put these kind of safety checks in place for different contexts um so now you have like even official recommendations to give you an example of chainalysis in their V2 solution they're saying we are recommending for the incoming transactions to to get at least 10 minutes time out uh because depending on a blockchain the the first block confirmation or and block confirmation that need to happen might take uh update especially if you're cheap on gas so what what you w to uh kind of make sure there is you're you know you you're thinking about this issue for your end users and customers because they're going to be impacted and actually making a balance between you know what you're doing is safe and good and but you're not taking too long in ideal word you're very fast when you're kind of developing these type of solutions and with that I'm going to thank you I think we're we're in the top of the hour so yeah do we have time for questions one question yeah yes so for example with the regulation we have Unis or and because of sanctions could it be possible that in the F yes yeah that could easily happen so it can go in let's say many different solutions from that point but practically if you let's say if we take a step back on on on the the current regulations if you take on the Offa sanction list for example like how is been like it's a very uh let's say um political way of defining who's on the Offa sanction list you know is been you know harvested contained you can say by the westal in a in a way to a certain extent and then when you say that like you C you today have blocks on different people organization and countries interacting which you know whichever let's say centralized exchange and and whatnot and you need to comply to that if you're going to get a license let's say I don't know you're applying for a Singapore license you need to prove you're not let's say interacting with a North Korean entity or you are making sure you're you have redundancies in place to to cut to cut that scenario and to make sure you know you're you're blocking them in a way so it's already happened today it's there the way it's going to happen and this um I think it's very interesting what you had with with the Z keys and and also it ties back in a way to a digital indentity piece on how is being managed and you know how do we build Solutions on top of that so I think different venues are going to have different kind of solutions to build that what we're see from at least my perspective what I'm seeing is that it's kind of getting uh you know we are in the stage of uh let's say early standard settings and we're going to have standard Wars in a way coming in in Next Period like who has the best travel rule uh contextualization like from the provider side of of different travel rule players who understand this best and because you have like philosophical and conceptual clashes between different providers today so at one point it's going to become like you know a bread and butter kind of like a global standard we we need to comply with how it's going to look like I don't think anybody knows at this stage but I think it's also uh interesting on how can we leverage the technology we know and we know we could have soon to solving these issues and we're seeing again from my perspective a growing number of regulators who are very eager to learn on how can we leverage the new technology to solve the let's say new and old problems we uh we had in the past in the field so yeah thank you all so much this was amazing this [Applause]
